Description
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2024-09 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-02T01:59:50.072Z
Reserved: 2024-04-05T13:59:17.190Z
Link: CVE-2024-31849
Updated: 2024-08-02T01:59:50.072Z
Status : Deferred
Published: 2024-04-05T18:15:09.563
Modified: 2026-06-17T07:28:49.923
Link: CVE-2024-31849
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')